-
Notifications
You must be signed in to change notification settings - Fork 197
chore: initialize fullsend per-repo installation #23216
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
robbycochran
wants to merge
1
commit into
master
Choose a base branch
from
fullsend/scaffold-install
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+198
−0
Open
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,24 @@ | ||
| # fullsend per-repo configuration | ||
| # https://github.com/fullsend-ai/fullsend | ||
| # | ||
| # This file configures fullsend for per-repo installation mode. | ||
| # See https://fullsend.sh/docs/guides/infrastructure/layered-config-reference | ||
| version: "1" | ||
| roles: | ||
| - triage | ||
| - coder | ||
| - review | ||
| - fix | ||
| - retro | ||
| - prioritize | ||
| allowed_remote_resources: | ||
| - https://raw.githubusercontent.com/fullsend-ai/fullsend/ | ||
| - https://raw.githubusercontent.com/fullsend-ai/agents/ | ||
| create_issues: | ||
| allow_targets: | ||
| repos: | ||
| - stackrox/stackrox | ||
| - fullsend-ai/fullsend | ||
| inference: | ||
| project: acs-ai-677887 | ||
| wif_provider: projects/741754573120/locations/global/workloadIdentityPools/fullsend-inference/providers/gh-stackrox-stackrox |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,123 @@ | ||
| # This file is managed by fullsend. Do not edit it directly. | ||
| # Upstream: https://github.com/fullsend-ai/fullsend/blob/main/internal/scaffold/fullsend-repo/.github/workflows/fullsend.yaml | ||
| --- | ||
| # fullsend shim workflow (per-repo installation mode) | ||
| # Routes events to agent workflows via reusable-dispatch.yml. | ||
| # All agent execution happens in this repo's context — no external | ||
| # config repo is needed. | ||
| # | ||
| # Security: pull_request_target runs the BASE branch version of this workflow, | ||
| # preventing PRs from modifying it to exfiltrate credentials. | ||
| # This shim never checks out PR code, so it is not vulnerable to "pwn request" | ||
| # attacks. | ||
| # | ||
| # Routing: this shim forwards the raw event context to reusable-dispatch.yml, | ||
| # which determines the stage and runs the agent inline (ADR 62). | ||
| # Adding a new stage requires only a job in reusable-dispatch.yml — zero changes to this repo. | ||
| # | ||
| # Concurrency: per-role cancel-in-progress groups live in reusable-dispatch.yml | ||
| # stage jobs with -agent- suffix. Roles operate independently (#2452). | ||
| name: fullsend | ||
|
|
||
| on: | ||
| issues: | ||
| types: [opened, edited, labeled] | ||
| issue_comment: | ||
| types: [created] | ||
| pull_request_target: | ||
| types: [opened, synchronize, ready_for_review, closed, labeled, unlabeled] | ||
| pull_request_review: | ||
| types: [submitted] | ||
|
|
||
| permissions: {} | ||
|
|
||
| jobs: | ||
| dispatch: | ||
| if: >- | ||
| (github.event_name != 'pull_request_target' && github.event_name != 'pull_request_review' | ||
| || github.event.pull_request.head.ref != 'fullsend/scaffold-install') | ||
| && (github.event_name != 'issue_comment' | ||
| || (startsWith(github.event.comment.body, '/fs-') | ||
| && github.event.comment.user.type != 'Bot')) | ||
| permissions: | ||
| actions: write | ||
| id-token: write | ||
| contents: write | ||
| issues: write | ||
| packages: read | ||
| pull-requests: write | ||
| uses: fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml@31c876374951d145e5ed8bc06681881666761dfb # v0.44.0 | ||
| with: | ||
| event_action: ${{ github.event.action }} | ||
| install_mode: per-repo | ||
| mint_url: ${{ vars.FULLSEND_MINT_URL }} | ||
| gcp_region: ${{ vars.FULLSEND_GCP_REGION }} | ||
| project_number: ${{ vars.FULLSEND_PROJECT_NUMBER }} | ||
| runner_image: ubuntu-24.04 | ||
| secrets: | ||
| FULLSEND_GCP_WIF_PROVIDER: ${{ secrets.FULLSEND_GCP_WIF_PROVIDER }} | ||
| FULLSEND_GCP_PROJECT_ID: ${{ secrets.FULLSEND_GCP_PROJECT_ID }} | ||
| FULLSEND_OPENAI_API_KEY: ${{ secrets.FULLSEND_OPENAI_API_KEY }} | ||
| OTEL_EXPORTER_OTLP_TRACES_HEADERS: ${{ secrets.OTEL_EXPORTER_OTLP_TRACES_HEADERS }} | ||
| OTEL_EXPORTER_OTLP_HEADERS: ${{ secrets.OTEL_EXPORTER_OTLP_HEADERS }} | ||
|
|
||
| stop-fix: | ||
| # Job-level if: is intentionally coarse — it only screens for the | ||
| # /fs-fix-stop command on a PR from a non-bot. The authoritative | ||
| # authorization decision (collaborator permission API + PR-author escape | ||
| # hatch) is made in the step below, so a maintainer whose author_association | ||
| # is not MEMBER (e.g. private org membership) is not filtered out (ADR 0054). | ||
| if: >- | ||
| github.event_name == 'issue_comment' | ||
| && github.event.issue.pull_request | ||
| && github.event.comment.user.type != 'Bot' | ||
| && github.event.comment.body == '/fs-fix-stop' | ||
| runs-on: ubuntu-24.04 | ||
| permissions: | ||
| contents: read | ||
| issues: write | ||
| pull-requests: write | ||
| steps: | ||
| - name: Add fullsend-no-fix label and notify | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| PR_NUMBER: ${{ github.event.issue.number }} | ||
| REPO: ${{ github.repository }} | ||
| COMMENT_USER_LOGIN: ${{ github.event.comment.user.login }} | ||
| ISSUE_USER_LOGIN: ${{ github.event.issue.user.login }} | ||
| run: | | ||
| set -euo pipefail | ||
| # ADR 0054: authorize via the collaborator permission API | ||
| # (admin|maintain|write), not author_association — the latter grants | ||
| # contributor status to anyone with a single merged PR (issue #5421). | ||
| # Mirrors has_repo_permission() in dispatch.yml; keep the two in sync. | ||
| # The PR author may always stop the fix agent on their own PR. | ||
| authorized=false | ||
| if [[ -n "$COMMENT_USER_LOGIN" && "$COMMENT_USER_LOGIN" == "$ISSUE_USER_LOGIN" ]]; then | ||
| authorized=true | ||
| else | ||
| if api_err=$(mktemp); then | ||
| if role=$(gh api "repos/$REPO/collaborators/$COMMENT_USER_LOGIN/permission" \ | ||
| --jq '.role_name' 2>"$api_err"); then | ||
| case "$role" in | ||
| admin|maintain|write) authorized=true ;; | ||
| esac | ||
| else | ||
| echo "::warning::Permission API call failed for $COMMENT_USER_LOGIN: $(cat "$api_err")" | ||
| fi | ||
| rm -f "$api_err" | ||
| else | ||
| echo "::warning::Failed to create temp file for permission check of $COMMENT_USER_LOGIN" | ||
| fi | ||
| fi | ||
| if [[ "$authorized" != "true" ]]; then | ||
| echo "::notice::User $COMMENT_USER_LOGIN is not authorized to stop the fix agent (requires write access or PR authorship)" | ||
| exit 0 | ||
| fi | ||
| gh label create "fullsend-no-fix" --repo "$REPO" \ | ||
| --description "Skip bot-triggered fix agent runs" --color "FBCA04" \ | ||
| --force 2>/dev/null || true | ||
| gh pr edit "$PR_NUMBER" --repo "$REPO" \ | ||
| --add-label "fullsend-no-fix" | ||
| gh pr comment "$PR_NUMBER" --repo "$REPO" \ | ||
| --body "Fix agent disabled for this PR. Remove the \`fullsend-no-fix\` label or use \`/fs-fix\` to re-engage." |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,51 @@ | ||
| # This file is managed by fullsend. Do not edit it directly. | ||
| # Upstream: https://github.com/fullsend-ai/fullsend/blob/main/internal/scaffold/fullsend-repo/.github/workflows/prioritize.yml | ||
| --- | ||
| # fullsend-stage: prioritize | ||
| name: Prioritize | ||
|
|
||
| permissions: | ||
| actions: write | ||
| contents: read | ||
| id-token: write | ||
| issues: write | ||
|
|
||
| on: | ||
| workflow_dispatch: | ||
| inputs: | ||
| event_type: | ||
| required: true | ||
| type: string | ||
| source_repo: | ||
| required: true | ||
| type: string | ||
| event_payload: | ||
| required: true | ||
| type: string | ||
| project_number: | ||
| description: GitHub Projects V2 project number for RICE scoring | ||
| required: false | ||
| type: string | ||
|
|
||
| concurrency: | ||
| group: fullsend-prioritize-${{ inputs.source_repo }}-${{ fromJSON(inputs.event_payload).issue.number }} | ||
| cancel-in-progress: true | ||
|
|
||
| jobs: | ||
| prioritize: | ||
| uses: fullsend-ai/fullsend/.github/workflows/reusable-prioritize.yml@31c876374951d145e5ed8bc06681881666761dfb # v0.44.0 | ||
| with: | ||
| event_type: ${{ inputs.event_type }} | ||
| source_repo: ${{ inputs.source_repo }} | ||
| event_payload: ${{ inputs.event_payload }} | ||
| mint_url: ${{ vars.FULLSEND_MINT_URL }} | ||
| gcp_region: ${{ vars.FULLSEND_GCP_REGION }} | ||
| project_number: ${{ inputs.project_number || vars.FULLSEND_PROJECT_NUMBER }} | ||
| install_mode: per-repo | ||
| runner_image: ubuntu-24.04 | ||
| secrets: | ||
| FULLSEND_GCP_WIF_PROVIDER: ${{ secrets.FULLSEND_GCP_WIF_PROVIDER }} | ||
| FULLSEND_GCP_PROJECT_ID: ${{ secrets.FULLSEND_GCP_PROJECT_ID }} | ||
| FULLSEND_OPENAI_API_KEY: ${{ secrets.FULLSEND_OPENAI_API_KEY }} | ||
| OTEL_EXPORTER_OTLP_TRACES_HEADERS: ${{ secrets.OTEL_EXPORTER_OTLP_TRACES_HEADERS }} | ||
| OTEL_EXPORTER_OTLP_HEADERS: ${{ secrets.OTEL_EXPORTER_OTLP_HEADERS }} | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Use a stable concurrency key for every payload.
When
inputs.event_payloadis valid JSON withoutissue.number, the current expression produces an empty value for that component. Runs from the samesource_repocan then share a concurrency group, andcancel-in-progress: truecan cancel an unrelated run. Invalid JSON can also make the expression fail.Update the upstream fullsend template so the group uses a payload field that the dispatcher always supplies, or validate and normalize the payload before constructing the group.
🤖 Prompt for AI Agents